Назад
Company hidden
3 дня назад

DevSecOps Adoption Practitioner (DevSecOps)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Romania
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
DevSecOps Adoption Practitioner (DevSecOps): Embedding security practices within engineering squads by configuring security tooling, reviewing code, and building compliance evidence pipelines with an accent on SAST/DAST, SBOM automation, secrets management, and IAM. Focus on triaging vulnerabilities with developers, enforcing CI/CD security gates, and enabling teams on secure coding and OWASP Top 10 practices.

Location: Cluj-Napoca, Romania; office attendance required three days per week

Company

hirify.global delivers software engineering services through distributed squads embedded in client product delivery teams.

What you will do

  • Review pull requests for vulnerabilities and explain security issues to developers in actionable terms.
  • Configure and maintain SAST tools including SonarQube, Checkmarx, and Semgrep within CI/CD pipelines.
  • Implement DAST scanning for APIs and services and triage findings with developers.
  • Generate and maintain SBOMs, automate release updates, and manage dependency scanning and vulnerability remediation.
  • Implement secrets management, credential rotation, least-privilege IAM, and security group and network policy reviews in AWS.
  • Produce security evidence for governance and InfoSec reviews and conduct enablement sessions on OWASP Top 10 and secure coding.

Requirements

  • 5+ years of security engineering or DevSecOps experience with hands-on security tooling.
  • Experience with SAST and DAST tools, including SonarQube, Checkmarx, Semgrep, OWASP ZAP, and Burp Suite.
  • Experience with SBOM standards and tools including CycloneDX, SPDX, Syft, and Grype.
  • Experience with dependency scanning, CVE triage, secrets management, and vulnerability remediation.
  • Experience with AWS IAM, least-privilege practices, and CI/CD security gates using GitHub Actions or Jenkins.
  • Proficient English at B2+ level for technical communication.

Nice to have

  • CSSLP, CEH, or AWS Security Specialty certification.
  • Experience with financial services regulatory compliance, including FCA or ISO 27001.
  • Background in web application or API penetration testing.

Culture & Benefits

  • Work on a long-term modernization program for a global financial markets infrastructure provider.
  • Vacation according to the laws of the country of employment.
  • Health insurance support for employees and their loved ones.
  • 10 days of sick pay without a doctor's note, followed by provisions under local law.
  • Time off for state holidays according to the official calendar.
  • Certification cost coverage, access to courses and learning platforms, and company social events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →